SecLists/Discovery/Web-Content
2025-12-04 14:07:38 +00:00
..
api fix(wordlist): Added missing terms to API Actions wordlist 2025-03-04 17:31:09 -03:00
BurpSuite-ParamMiner
CMS [Github Action] Automated trickest wordlists update. 2025-12-04 10:08:14 +00:00
Domino-Hunter
dutch chore(wordlist): Removed duplicate wordlist 'without_spaces.txt' 2025-02-22 03:20:03 -03:00
File-Extensions-Universal-SVNDigger-Project
LEGACY-SERVICES feat(docs): Added criteria for the LEGACY-SERVICES category 2025-02-21 21:01:10 -03:00
Programming-Language-Specific feat(wordlist): Update list of Spring endpoints. (PR #1253) 2025-10-11 21:10:44 -03:00
Service-Specific feat(wordlist): Added more payloads to Swagger.txt 2025-11-27 22:49:54 -03:00
trickest-robots-disallowed-wordlists [Github Action] Automated trickest wordlists update. 2025-12-04 14:07:38 +00:00
URLs Added url used in CVE-2025-31324 to urls-SAP.txt 2025-04-28 18:09:13 +02:00
Web-Servers feat(docs): Added documentation for 'IIS-POST.txt' 2025-02-21 23:03:11 -03:00
ActiveDirectory-small.txt Create ActiveDirectory-small.txt 2025-06-30 10:21:33 -07:00
AdobeXML.fuzz.txt
big.txt feat(wordlist): Added readme.md to "Discovery/Web-Content/big.txt" 2025-09-12 16:13:53 +02:00
burp-parameter-names.txt
coldfusion.txt
combined_directories.txt [Github Action] Updated combined_directories.txt 2025-09-19 05:51:28 +00:00
combined_words.txt [Github Action] Updated combined_words.txt 2025-09-13 08:04:29 +00:00
common-api-endpoints-mazen160.txt
Common-DB-Backups.txt
common.txt feat(wordlist): Added mcp-server.txt entries to common.txt 2025-06-21 19:54:12 -03:00
common_directories.txt feat(wordlist): Added more permutations to 'common_directories.txt' 2025-07-17 19:58:20 -03:00
default-web-root-directory-linux.txt
default-web-root-directory-windows.txt
DirBuster-2007_directory-list-2.3-big.txt fix(wordlist): Added 'DirBuster-2007' prefix to all DirBuster wordlists 2025-07-17 20:07:31 -03:00
DirBuster-2007_directory-list-2.3-medium.txt fix(wordlist): Added 'DirBuster-2007' prefix to all DirBuster wordlists 2025-07-17 20:07:31 -03:00
DirBuster-2007_directory-list-2.3-small.txt fix(wordlist): Added 'DirBuster-2007' prefix to all DirBuster wordlists 2025-07-17 20:07:31 -03:00
DirBuster-2007_directory-list-lowercase-2.3-big.txt fix(wordlist): Added 'DirBuster-2007' prefix to all DirBuster wordlists 2025-07-17 20:07:31 -03:00
DirBuster-2007_directory-list-lowercase-2.3-medium.txt fix(wordlist): Added 'DirBuster-2007' prefix to all DirBuster wordlists 2025-07-17 20:07:31 -03:00
DirBuster-2007_directory-list-lowercase-2.3-small.txt fix(wordlist): Added 'DirBuster-2007' prefix to all DirBuster wordlists 2025-07-17 20:07:31 -03:00
domino-dirs-coldfusion39.txt
domino-endpoints-coldfusion39.txt
dsstorewordlist.txt
graphql.txt
hashicorp-consul-api.txt
hashicorp-vault.txt
JavaScript-Miners.txt
JavaServlets-Common.fuzz.txt
LinuxFileList.txt
Logins.fuzz.txt
mcp-server.txt feat(wordlist): Added a dictionary for Model Context Protocol server discovery. (PR #1216) 2025-06-21 15:53:26 -03:00
Microsoft-Frontpage.txt
netware.txt
ntlm-directories.txt
oauth-oidc-scopes.txt
Oracle9i.fuzz.txt
OracleAppServer.fuzz.txt
Passwords.fuzz.txt
Proxy-Auto-Configuration-Files.txt fix(wordlist): Renamed 'proxy-conf.fuzz.txt' to 'Proxy-Auto-Configuration-Files.txt' 2025-02-21 22:59:10 -03:00
Public-Source-Repo-Issues.json
quickhits.txt
raft-large-directories-lowercase.txt fix(wordlist): Fixed bad formatting in raft-* wordlists 2025-02-22 04:56:43 -03:00
raft-large-directories.txt fix(wordlist): Fixed bad formatting in raft-* wordlists 2025-02-22 04:56:43 -03:00
raft-large-extensions-lowercase.txt
raft-large-extensions.txt
raft-large-files-lowercase.txt
raft-large-files.txt
raft-large-words-lowercase.txt
raft-large-words.txt
raft-medium-directories-lowercase.txt fix(wordlist): Fixed bad formatting in raft-* wordlists 2025-02-22 04:56:43 -03:00
raft-medium-directories.txt fix(wordlist): Fixed bad formatting in raft-* wordlists 2025-02-22 04:56:43 -03:00
raft-medium-extensions-lowercase.txt
raft-medium-extensions.txt
raft-medium-files-lowercase.txt
raft-medium-files.txt
raft-medium-words-lowercase.txt
raft-medium-words.txt
raft-small-directories-lowercase.txt fix(wordlist): Fixed bad formatting in raft-* wordlists 2025-02-22 04:56:43 -03:00
raft-small-directories.txt fix(wordlist): Fixed bad formatting in raft-* wordlists 2025-02-22 04:56:43 -03:00
raft-small-extensions-lowercase.txt
raft-small-extensions.txt
raft-small-files-lowercase.txt
raft-small-files.txt
raft-small-words-lowercase.txt
raft-small-words.txt
README.md fix(docs): Updated filenames that compose 'combined_directories.txt' 2025-07-17 20:11:15 -03:00
reverse-proxy-inconsistencies.txt
Roundcube-123.txt
rssfeed-files.txt
sap-analytics-cloud.txt
SAP-NetWeaver.txt feat(wordlist): added entries to "SAP-NetWeaver.txt" 2025-10-13 17:11:51 +10:00
SOAP-functions.txt
tftp.fuzz.txt
UnixDotfiles.fuzz.txt
uri-from-top-55-most-popular-apps.txt
url-params_from-top-55-most-popular-apps.txt
versioning_metafiles.txt
vulnerability-scan_j2ee-websites_WEB-INF.txt
web-all-content-types.txt feat(wordlist): Added IANA mime-types to "web-all-content-types.txt" (PR #1204) 2025-05-26 03:24:29 -03:00
web-extensions-big.txt
web-extensions.txt
web-mutations.txt
wso2-enterprise-integrator.txt fix(wordlist): Remove potentially dangerous payload from the 'wso2-enterprise' wordlist (PR #1268) 2025-11-25 19:29:47 -03:00

Web discovery wordlists

AdobeXML.fuzz.txt

Use for: Discovering sensitive filepaths of Adobe ColdFusion

Creation date: Aug 27, 2012

No updates have been made to this wordlist since its creation.

raft-* wordlists

Use for: Directory and file brute-forcing leading to identification of vulnerabilities in web applications.

Source: Google's RAFT

combined_words.txt

Use for: discovering files
This list is automatically updated by a github action whenever any of the lists it's composed by is modified.

This list is a combination of the following wordlists:

  • big.txt
  • common.txt
  • raft-large-words-lowercase.txt
  • raft-large-words.txt
  • raft-medium-words-lowercase.txt
  • raft-medium-words.txt
  • raft-small-words-lowercase.txt
  • raft-small-words.txt

combined_directories.txt

Use for: discovering files and directories

This list is automatically updated by a github action whenever any of the lists it's composed by is modified.

These are the wordlists that compose this wordlist:

  • apache.txt
  • combined_words.txt
  • DirBuster-2007_directory-list-2.3-big.txt
  • DirBuster-2007_directory-list-2.3-medium.txt
  • DirBuster-2007_directory-list-2.3-small.txt
  • raft-large-directories-lowercase.txt
  • raft-large-directories.txt
  • raft-medium-directories-lowercase.txt
  • raft-medium-directories.txt
  • raft-small-directories-lowercase.txt
  • raft-small-directories.txt
  • common_directories.txt

dsstorewordlist.txt

Use for: discovering files and directories

This wordlist was collected by parsing Alexa top-million sites for .DS_Store files, extracting all the found files, and then extracting found file and directory names from around 300k real websites. The files were then sorted by probability and one-occurrence strings were removed.

Source: https://github.com/aels/subdirectories-discover

vulnerability-scan_j2ee-websites_WEB-INF.txt

Use for: discovering sensitive j2ee files exploiting a lfi

References:

Microsoft-Frontpage.txt

Use for: Fuzzing for common filepaths in webpages designed with Microsoft Frontpage

Year of the first release of Microsoft Frontpage: 1997

Year of the last release of Microsoft Frontpage: 2003

Date of last update: Oct 14, 2010

graphql.txt

Use for: Fuzzing for common filepaths in webpages that use the GraphQL Query Language

reverse-proxy-inconsistencies.txt

Use for: Detecting the backend admin/console interfaces and tomcat manager interfaces hiding behind reverse proxies by leveraging inconsistencies in how certain requests are handled.

See: A fresh look on reverse proxy related attacks | acunetix.com | Aleksei Tiurin | 2019-01-22

web-all-content-types.txt

Use for: Discovering allowed media types (aka MIME types, content types), typically for file uploads in web applications. Note: List contains all lowercase values for consistency and to follow standard convention. According to RFC 2045, MIME types, subtypes, and parameter names are not case-sensitive. However, in the wild, some servers may accept uppercase values while rejecting lowercase equivalents.

Date updated: May 24, 2025

Official source: https://www.iana.org/assignments/media-types/media-types.xhtml

mcp-server.txt

Use for: Discover instances of a Model Context Protocol server.

Date updated: June 21, 2025

Sources: